Privacy Policy


Pulp Strategy Communications Private Limited (CIN: U74140DL2011PTC216407), trading as NeuroRank, is committed to protecting your personal data and your privacy. This Privacy Policy explains what information we collect, why we collect it, how we use and protect it, and what rights you have. It applies to all users of https://neurorank.ai, our web application, and any related tools or communications, regardless of where you are located in the world.

 

This policy governs data we collect when you use the NeuroRank platform as a user. It does not apply to data we process on behalf of business customers in our capacity as a data processor; that processing is governed by the Data Processing Addendum (Policy 9 of this document).

 

By using NeuroRank you confirm that you have read and understood this policy.

 

1. Who We Are

NeuroRank is owned and operated by Pulp Strategy Communications Private Limited, incorporated in India (CIN: U74140DL2011PTC216407), with its registered office in New Delhi, India. We are the data controller for personal data collected through this platform.

 

For formal legal or data protection notices: legal@neurorank.ai. For all other queries: https://neurorank.ai/contact.

 

EU and UK users: NeuroRank is an India-based SaaS company with no physical presence in the EU or UK. We serve global users online only. We take all data protection obligations seriously and respond to rights requests within required timeframes. We do not currently have a formal EU Article 27 representative; we will appoint one when our EU user base makes this appropriate. Our legal contact for GDPR matters is legal@neurorank.ai.

 

2. What Personal Data We Collect

2.1 Account and Registration Data

  • Full name and email address
  • Company name and job title (optional but improves scoring accuracy)
  • Password (stored as a one-way cryptographic hash; we cannot read it)
  • Billing name and address (for paid plans)

2.2 Usage and Platform Data

  • Brand names, URLs, and competitor data you enter into the platform
  • Search queries, scoring inputs, and analysis requests
  • NeuroRank score history and audit results associated with your account
  • Feature usage patterns, frequency of use, and tool interactions
  • Time and date of platform interactions
  • Beta feature access, participation, and feedback where applicable

2.3 Technical and Device Data

  • IP address and approximate geolocation (country and city level only)
  • Browser type and version, operating system, and device type
  • Session identifiers and authentication tokens
  • Pages visited, click paths, and session duration
  • Referring URLs
  • Timezone and language preferences

2.4 Payment Data

We do not store full payment card details. Payment processing is handled by our payment processor (Stripe or Razorpay, as applicable). We receive only a tokenised reference and the last four digits of your card. Your payment processor’s privacy policy governs how card data is stored and processed.

 

2.5 Communications Data

  • Messages you submit to us via the contact form
  • Support interactions and correspondence
  • Responses to surveys or feedback requests
  • Records of your marketing preferences and consent status

2.6 Data You Input About Third Parties

When you enter competitor brand names, URLs, or other brand data, that data is processed on your behalf. We treat it as platform input and handle it with the same care as all platform data. You represent and warrant that you have the right to submit such data and that doing so does not violate any third party’s rights. Where you provide personal data of third parties (for example, a named individual), you are responsible for ensuring you have a lawful basis for sharing that data with us.

 

2.7 Third-Party Tool Integrations

If you connect third-party accounts (such as Google Search Console or Google Analytics) to your NeuroRank account, we may process data from those accounts solely to provide the connected feature. This integration is at your discretion and may be revoked at any time. We will not use data from third-party integrations for advertising or profiling.

 

2.8 Tracking Technologies and Advertising Data

We and our analytics and advertising partners may use cookies, web beacons, tracking pixels, and similar technologies. These may collect your IP address, pages visited, and platform behaviour. See our Cookie Policy (Policy 4) for full details. Where we use social media advertising pixels (such as LinkedIn Insight Tag or Meta Pixel), these may constitute data sharing with those platforms governed by their own privacy policies. You can manage these through our cookie preference centre.

 

2.9 Aggregate and Anonymised Data

We may generate aggregate, anonymised data from platform usage to publish industry benchmarks, improve our scoring models, and develop new features. Once fully anonymised, this data can no longer identify you and is not personal data subject to this policy. You expressly consent to this use as part of your agreement with us.

 

3. How We Use Your Data

Purpose Legal Basis Retention Period
Provide and maintain your account and platform access Contract performance Duration of account + 30 days after deletion
Process payments and manage billing Contract performance 7 years (tax / legal requirement)
Deliver NeuroRank scoring, audits, and analysis Contract performance Duration of subscription + 90 days
Improve platform features, fix bugs, and enhance performance Legitimate interests Anonymised after 12 months
Send transactional emails (invoices, alerts, account notices) Contract performance Duration of account
Send product updates and marketing emails (with consent) Consent Until consent withdrawn
Comply with legal obligations (tax, fraud prevention, court/government orders) Legal obligation As required by applicable law
Aggregate analysis to improve AI scoring accuracy Legitimate interests (consent in ToS) Anonymised; no retention limit
Respond to support requests Legitimate interests / Contract 1 year from last interaction
Fraud detection, security, and abuse prevention Legitimate interests / Legal obligation 3 years or as required by law
Review communications for fraud prevention and service improvement Legitimate interests Duration of account; anonymised after 12 months
Respond to government, regulatory, or public authority requests Legal obligation As required by applicable law
Data analysis, benchmarking, audits, research, and usage trend identification Legitimate interests Anonymised after 12 months

Communications Review

We may review, scan, or analyse your communications on the platform for fraud prevention, risk assessment, regulatory compliance, product improvement, and support purposes. We use automated methods where possible. Manual review occurs only where necessary. We will not use this for third-party marketing purposes.

 

4. Who We Share Your Data With

We do not sell your personal data. We do not share it with third parties for their own marketing purposes. We share data only where necessary:

 

4.1 Service Providers (Data Processors)

Provider Purpose and Notes
Stripe / Razorpay (as applicable) Payment processing. PCI DSS compliant. Does not receive browsing data.
Amazon Web Services or equivalent Cloud hosting and infrastructure. Data stored in selected regions.
Google Analytics (GA4) Aggregated usage analytics. IP anonymisation enabled. Data sharing with Google restricted.
Customer support platform Support messaging. Contact form submissions routed here.
Transactional email provider Delivery of account and billing emails only.
Anthropic (Claude API) AI analysis and recommendation features. Enterprise API terms: inputs not used for model training.
Google (Gemini API, where used) AI-powered features. Governed by Google Cloud DPA.
OpenAI (where used) AI-powered features. Enterprise API terms: inputs not used for model training.
Perplexity AI (where used) Search and citation analysis features. API terms apply.
All service providers are bound by Data Processing Agreements (DPAs) and may only process data on our documented instructions. We will update this table when we add material new providers.

 

4.2 Social Networks and Advertising

Where we run advertising campaigns, we may share limited, hashed personal data (such as your email address) with social platforms such as LinkedIn or Meta to build advertising audiences. This is based on our legitimate interests in marketing. You may opt out at any time via our cookie preference centre or by contacting us.

 

4.3 Requests from Government and Public Authorities

We may disclose your data in response to lawful requests from government, regulatory, or public authorities, including requests from authorities outside your country of residence, where we are required to do so by law. Where legally permitted, we will notify you of such requests. We will only share the minimum data required.

 

4.4 Legal Enforcement

We may share data to enforce our Terms of Service, protect the rights, safety, or property of NeuroRank, our users, or the public, or to investigate potential violations of our policies.

 

4.5 Business Transfers

If Pulp Strategy Communications Private Limited is acquired, merged, or its assets are transferred, your data may transfer to the acquiring entity. We will notify you via email and/or a prominent notice on the platform at least 30 days before any such transfer takes effect.

 

5. International Data Transfers

NeuroRank operates globally from India. Your data may be processed in countries outside your own, including the United States (via cloud and AI service providers). We ensure all international transfers are protected by:
  • Standard Contractual Clauses (SCCs) with EU/UK service providers
  • Vendor participation in the EU-US Data Privacy Framework
  • Contractual data protection obligations under applicable law
You may request details of transfer safeguards by contacting legal@neurorank.ai.

 

6. Data Retention

We retain personal data only as long as necessary to provide our services and meet legal obligations. Retention periods are set out in Section 3. When data is no longer needed we securely delete or anonymise it. Backup systems are purged within 90 days of a deletion request being fulfilled. We may retain data longer where required to establish, exercise, or defend legal claims.

 

7. Your Privacy Rights

Right What It Means Applies Under
Access Request a copy of all personal data we hold about you GDPR, CCPA, India DPDPA, global
Rectification / Correction Correct inaccurate or incomplete data GDPR, CCPA, most global laws
Erasure / Deletion Request deletion (subject to legal exceptions) GDPR, CCPA
Portability Receive your data in a machine-readable format GDPR
Restriction Pause processing while a dispute is resolved GDPR
Object Object to processing based on legitimate interests GDPR
Withdraw Consent Withdraw marketing consent at any time without penalty GDPR, global
Opt-Out of Sale / Sharing Opt out of any sale or sharing of personal information CCPA / CPRA
Non-Discrimination Exercise rights without receiving inferior service CCPA / CPRA
Complaint Lodge a complaint with your national data protection authority GDPR, UK GDPR
To exercise any right, submit a request at https://neurorank.ai/contact or email legal@neurorank.ai for formal legal notices. We respond within 30 days (extendable to 90 days for complex requests with advance notice). No fee is charged unless a request is manifestly unfounded or excessive. If we cannot fully comply, we will explain why.

 

If you are not satisfied with our response, you may complain to the supervisory authority in your country. EU users may contact their national data protection authority. UK users may contact the ICO (ico.org.uk). We would appreciate the opportunity to address your concern directly first.

 

8. Security

  • TLS/HTTPS encryption for all data in transit
  • AES-256 encryption for data at rest
  • Role-based access controls and least-privilege principles
  • Regular security audits and penetration testing
  • Two-factor authentication (2FA) available for all accounts
  • Web Application Firewall (WAF) and DDoS protection
  • Incident response procedures and breach notification aligned with applicable law
In the event of a data breach likely to result in risk to your rights and freedoms, we will notify you promptly and take all reasonable steps to mitigate harm. If you suspect unauthorised access to your account, report it immediately via https://neurorank.ai/contact.

 

9. Sensitive Information

NeuroRank is not designed to collect or process sensitive personal information, including health data, financial account numbers, biometric data, government ID numbers, racial or ethnic origin, political opinions, religious beliefs, or criminal records. You must not submit sensitive personal information to the platform. If we identify that sensitive information has been submitted, we will delete it and may suspend the relevant account. We expressly disclaim any liability arising from your submission of sensitive information to the platform.

 

10. Children’s Privacy

NeuroRank is not directed to individuals under 18. We do not knowingly collect personal data from minors. If you believe a person under 18 has provided us personal data, contact us via https://neurorank.ai/contact and we will delete it promptly.

 

11. India-Specific Provisions

NeuroRank complies with the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

 

We implement reasonable security practices as required. The Digital Personal Data Protection Act, 2023 (DPDPA) will apply to our processing activities as its provisions come into force; we will update this policy accordingly.

 

12. Changes to This Policy

We may update this Privacy Policy at any time. We will notify you of material changes by email and/or by a prominent notice on the platform at least 14 days before the change takes effect. The current version is always available at https://neurorank.ai/legal.

 

13. Contact

All queries and privacy requests: https://neurorank.ai/contact
Legal / GDPR / formal notices: legal@neurorank.ai
Company: Pulp Strategy Communications Private Limited
CIN: U74140DL2011PTC216407
Registered office: New Delhi, India

 

Scroll to Top